Heartbleed: Eight Tips and Strategies for Keeping Safe

Share  
1  |  2  |  3  |  4  |  5  |  6  |  7  |  8  |  9  |  10
Previous Next

Click through for eight important tips and strategies for keeping data safe, as identified by LogRhythm Labs.

Topics : Unisys, Stimulus Package, Security Breaches, Symantec, Electronic Surveillance

One of the most dangerous IT security threats of all time emerged recently – a bug called Heartbleed, which quickly sent shockwaves throughout the entire industry.


As a result, Fortune 500 organizations have been racing to patch their networks before hackers exploit the vulnerability and steal important, private data. Consumers are also encouraged to change their passwords after the systems have been patched.

The vulnerability emerged from the open source software universe. It was exposed to the Internet before a patch was made available, technically making it a zero-day vulnerability, and forcing IT administrators and security analysts to respond as quickly as possible to a previously unknown threat.

OpenSSL provides encryption to services such as SSL and TLS, which are primarily used for securing Web application traffic and reducing the risk of someone stealing credentials or other sensitive data while in transit. The vulnerability arose from a simple programming error in certain releases of the OpenSSL library (1.0.1-1.0.1f). It's technically referred to as a Buffer Over Read in that once the exploit is successful, 64k of the server's memory 'leaks' and can then be viewed by an unauthorized party.

This is significant in that very sensitive data can be contained within the server's memory, which could include anything from usernames, passwords, account numbers, private keys, session tokens and much more. Successful exploitation of this vulnerability is also trivially easy to pull off, opening the door for many unskilled 'hackers' to gain access to sensitive, private information.

What's more, if secret keys are stolen, this can allow the attacker to man-in-the-middle any traffic destined for the application, allowing them to snoop on private and sensitive application interactions such as financial transactions.

Here are eight important tips and strategies to keep data safe, as identified by LogRhythm Labs.

 

More Slideshows

AlienVaultCFOSecurityInvestment0x Five Ways a CFO Can Invest in Securing Their Organization

Considering the costs related to security, it's no wonder that the CFO might struggle a bit in regards to investing in this part of the business. ...  More >>

Lumension10QsSecurityVendors0x 2015 Endpoint and Mobile Security Procurement: 10 Questions to Ask New Vendors

In the spirit of 2015 planning, now is the time of year when IT teams start to tackle big, complicated issues like endpoint and mobile security. ...  More >>

Security41-190x128 Cybersecurity Grades Released for Key Industries

Looking at cyber data through a business intelligence lens ensures that security-related trends and potential impacts to organizations can be understood and effectively addressed. ...  More >>

Subscribe to our Newsletters

Sign up now and get the best business technology insights direct to your inbox.